ISO 9001:2026 Audit Checklist: Free Clause-by-Clause Internal Audit Checklist

[Download the Free ISO 9001 Audit Checklist]

Prepare for your next ISO 9001 internal audit with a practical, clause-by-clause checklist covering the QMS requirements, audit questions, objective evidence, findings, and corrective actions.

Whether you are preparing for an internal audit, a certification audit, a surveillance audit, or simply evaluating the effectiveness of your Quality Management System, this checklist can help your audit team organize the review and identify areas requiring attention.

ISO 9001 update: ISO 9001:2026 is now the current edition of the standard. Organizations transitioning from ISO 9001:2015 should confirm applicable transition arrangements with their certification body.

What Is an ISO 9001 Audit Checklist?

 

An ISO 9001 audit checklist is a structured set of questions and evidence prompts used by auditors to assess whether an organization's Quality Management System (QMS) is effectively implemented and conforms to applicable ISO 9001 requirements.

A good audit checklist should do more than ask whether a procedure exists.

It should help the auditor determine:

  • Whether the required processes have been established and implemented
  • Whether employees understand and follow those processes
  • Whether objective evidence demonstrates that processes are working
  • Whether quality objectives are being monitored and achieved
  • Whether risks and opportunities are being addressed
  • Whether nonconformities are investigated and corrected
  • Whether corrective actions are effective
  • Whether the QMS is continually improved

This checklist is designed as a practical starting point for internal auditors. It should be adapted to the organization's scope, processes, products, services, risks, and applicable requirements.

ISO 9001 Audit Checklist: Clauses 4–10

 

ISO 9001 requirements are organized around the organization's context, leadership, planning, support, operation, performance evaluation, and improvement.

Use the following checklist to guide an internal audit.

Clause 4 - Context of the Organization

 

4.1 Understanding the Organization and Its Context

 

Audit questions

  • Has the organization identified internal and external issues that can affect the intended results of the QMS?
  • Are relevant business, technological, market, regulatory, and organizational changes monitored?
  • Are significant changes in the organization's context reviewed periodically?
  • Can management explain which issues are most important to the effectiveness of the QMS?

Objective evidence to consider

  • Context analysis
  • SWOT or equivalent analysis
  • Business planning records
  • Risk and opportunity records
  • Management review records
  • Strategic planning documents
  • Records demonstrating review of significant changes

4.2 Understanding the Needs and Expectations of Interested Parties

 

Audit questions

  • Has the organization identified relevant interested parties?
  • Have relevant requirements of customers, regulators, employees, suppliers and other interested parties been identified?
  • Are changes in relevant requirements monitored?
  • Are these requirements considered when operating and improving the QMS?

Objective evidence to consider

  • Interested-party register
  • Customer requirements
  • Regulatory requirements
  • Contracts
  • Supplier requirements
  • Applicable statutory requirements
  • Management review records

 

4.3 Determining the Scope of the QMS

 

Audit questions

  • Is the scope of the QMS clearly defined?
  • Does the scope identify the organization's relevant products, services, locations and activities?
  • Is the scope consistent with the organization's context and processes?
  • Are any requirements determined to be not applicable appropriately justified?

Objective evidence to consider

  • Approved QMS scope
  • Quality manual or equivalent information
  • Process maps
  • Organization structure
  • Site and facility information

4.4 Quality Management System and Its Processes

 

Audit questions

  • Have the processes required for the QMS been identified?
  • Are process inputs, outputs, responsibilities and interactions understood?
  • Are criteria and methods established to ensure effective process operation?
  • Are process risks and opportunities addressed?
  • Are process performance and effectiveness monitored?
  • Are processes improved when necessary?

Objective evidence to consider

  • Process maps
  • Process owners
  • SOPs and work instructions
  • KPIs
  • Process performance records
  • Risk assessments
  • Audit findings
  • Improvement actions

Clause 5 - Leadership

 

5.1 Leadership and Commitment

 

Audit questions

  • Does top management demonstrate accountability for the effectiveness of the QMS?
  • Is the QMS integrated into the organization's business processes?
  • Is customer focus demonstrated?
  • Are adequate resources provided for the QMS?
  • Does management promote process-based thinking and continual improvement?
  • Does management support people who contribute to QMS effectiveness?

Objective evidence to consider

  • Management review records
  • Business objectives
  • Resource planning
  • Quality objectives
  • Meeting records
  • Improvement initiatives
  • Management communications

5.2 Quality Policy

 

Audit questions

  • Has a quality policy been established?
  • Is the policy appropriate to the organization's purpose and context?
  • Does it provide a framework for establishing quality objectives?
  • Does it demonstrate commitment to applicable requirements and continual improvement?
  • Is the policy communicated and understood within the organization?
  • Is the policy available to relevant interested parties where appropriate?

Objective evidence to consider

  • Approved quality policy
  • Employee communication records
  • Training or awareness records
  • Internal communications
  • Posted or electronically controlled policy

5.3 Organizational Roles, Responsibilities and Authorities

 

Audit questions

  • Are QMS responsibilities clearly defined?
  • Are authorities communicated to relevant personnel?
  • Is responsibility for ensuring QMS conformity assigned?
  • Is responsibility for reporting QMS performance assigned?
  • Do employees understand their quality-related responsibilities?

Objective evidence to consider

  • Organization chart
  • Job descriptions
  • Responsibility matrix
  • Delegation records
  • Employee interviews

Clause 6 - Planning

 

6.1 Actions to Address Risks and Opportunities

 

Audit questions

  • Have relevant QMS risks and opportunities been identified?
  • Are risks evaluated using defined criteria?
  • Are actions planned for significant risks and opportunities?
  • Are risk-control actions integrated into QMS processes?
  • Is the effectiveness of actions evaluated?
  • Are risks reviewed when processes, products or circumstances change?

Objective evidence to consider

  • Risk register
  • Process risk assessments
  • FMEA or equivalent tools
  • Action plans
  • Risk review records
  • CAPA records
  • Change control records

6.2 Quality Objectives and Planning to Achieve Them

 

Audit questions

  • Have quality objectives been established for relevant functions and levels?
  • Are objectives measurable where appropriate?
  • Are objectives monitored and reviewed?
  • Are responsibilities and resources defined?
  • Are target dates established?
  • Are results evaluated and acted upon?

Objective evidence to consider

  • Quality objectives
  • KPI dashboards
  • Department objectives
  • Performance reports
  • Management review records
  • Improvement plans

6.3 Planning of Changes

 

Audit questions

  • Are significant QMS changes planned before implementation?
  • Are the purpose and potential consequences of changes evaluated?
  • Are QMS integrity and process interactions considered?
  • Are responsibilities and resources defined?
  • Are affected documents, processes and personnel identified?

Objective evidence to consider

  • Change control records
  • Change requests
  • Impact assessments
  • Approval records
  • Updated procedures
  • Training records

Clause 7 - Support

 

7.1 Resources

 

Audit questions

  • Are sufficient resources available to operate the QMS effectively?
  • Is required infrastructure available and maintained?
  • Are appropriate work environments provided?
  • Are monitoring and measuring resources suitable and maintained?
  • Where applicable, are organizational knowledge and knowledge needed to operate processes maintained and made available?

Objective evidence to consider

  • Resource plans
  • Equipment records
  • Maintenance records
  • Calibration records
  • Infrastructure records
  • Knowledge repositories
  • Competency records

7.2 Competence

 

Audit questions

  • Are competency requirements defined for personnel performing QMS-related work?
  • Are personnel competent based on education, training or experience?
  • Are competency gaps identified?
  • Is training provided where necessary?
  • Is the effectiveness of actions taken to achieve competence evaluated?

Objective evidence to consider

  • Job descriptions
  • Competency matrices
  • Training records
  • Qualification records
  • Training effectiveness evaluations
  • Employee assessments

7.3 Awareness

 

Audit questions

  • Are employees aware of the quality policy?
  • Do employees understand relevant quality objectives?
  • Do employees understand how their work contributes to QMS effectiveness?
  • Are employees aware of the consequences of failing to follow QMS requirements?

Objective evidence to consider

  • Awareness training
  • Employee interviews
  • Induction records
  • Communication materials
  • Training assessments

7.4 Communication

 

Audit questions

  • Has the organization determined what needs to be communicated?
  • Is it clear who communicates quality-related information?
  • Are internal communication methods effective?
  • Are relevant external communications controlled?

Objective evidence to consider

  • Communication procedures
  • Meeting records
  • Quality alerts
  • Customer communications
  • Supplier communications
  • Internal announcements

7.5 Documented Information

 

Audit questions

  • Is required documented information available and suitable for use?
  • Are documents appropriately identified and described?
  • Are documents reviewed and approved before use?
  • Is document revision status controlled?
  • Are current versions available at points of use?
  • Are obsolete documents prevented from unintended use?
  • Are externally originated documents controlled where necessary?
  • Are records adequately protected, retained and retrievable?

Objective evidence to consider

  • Document register
  • Controlled SOPs
  • Revision history
  • Approval records
  • Distribution records
  • Document access controls
  • Retention schedules
  • Archived records
  • Audit trails

Common audit risks

Look particularly for:

  • Uncontrolled copies
  • Outdated SOPs
  • Missing approvals
  • Documents being used before approval
  • Inconsistent versions across departments
  • Missing training records for revised documents
  • Inadequate retention controls

Clause 8 - Operation

 

8.1 Operational Planning and Control

 

Audit questions

  • Are operational processes planned and controlled?
  • Are process criteria established?
  • Are required resources available?
  • Are required records retained?
  • Are planned changes controlled?
  • Are unintended changes reviewed and addressed?

Objective evidence to consider

  • SOPs
  • Work instructions
  • Production records
  • Service records
  • Process controls
  • Quality plans
  • Inspection records

8.2 Requirements for Products and Services

 

Audit questions

  • Are customer requirements identified?
  • Are applicable statutory and regulatory requirements determined?
  • Are requirements reviewed before accepting an order or commitment?
  • Are changes to customer requirements communicated?
  • Are customer communications controlled?

Objective evidence to consider

  • Contracts
  • Purchase orders
  • Customer specifications
  • Order review records
  • Customer communications
  • Change requests

8.3 Design and Development of Products and Services (Where applicable)

 

Audit questions

  • Is design and development planning controlled?
  • Are design inputs identified and reviewed?
  • Are design outputs suitable for subsequent processes?
  • Are design reviews conducted as planned?
  • Are verification and validation activities performed where required?
  • Are design changes identified, reviewed and controlled?

Objective evidence to consider

  • Design plans
  • Specifications
  • Design reviews
  • Verification records
  • Validation records
  • Engineering changes
  • Approval records

8.4 Control of Externally Provided Processes, Products and Services

 

Audit questions

  • Are external providers evaluated and selected using defined criteria?
  • Are supplier performance and re-evaluation controlled?
  • Are purchasing requirements clearly defined?
  • Are supplier quality requirements communicated?
  • Are incoming products or services verified as appropriate?
  • Are supplier nonconformities identified and addressed?

Objective evidence to consider

  • Approved supplier list
  • Supplier evaluation
  • Supplier scorecards
  • Purchase specifications
  • Incoming inspection
  • Supplier audits
  • Supplier NCRs
  • Supplier corrective actions

8.5 Production and Service Provision

 

Audit questions

  • Are production and service activities carried out under controlled conditions?
  • Are appropriate documented information and work instructions available?
  • Is required monitoring and measurement performed?
  • Is identification and traceability maintained where applicable?
  • Are customer or external-provider property controls established?
  • Are outputs preserved throughout operations?
  • Are post-delivery activities controlled where applicable?

Objective evidence to consider

  • Work instructions
  • Batch records
  • Production records
  • Inspection records
  • Traceability records
  • Equipment records
  • Preservation records

8.6 Release of Products and Services

 

Audit questions

  • Are required verification and inspection activities completed before release?
  • Are acceptance criteria satisfied?
  • Is release authorization documented?
  • Can the organization identify who authorized release?

Objective evidence to consider

  • Inspection reports
  • Test reports
  • Release records
  • Certificates
  • Approval records
  • Batch release documentation

8.7 Control of Nonconforming Outputs

 

Audit questions

  • Are nonconforming outputs identified and controlled?
  • Are appropriate actions taken to prevent unintended use or delivery?
  • Are decisions regarding disposition documented?
  • Is rework or correction verified where appropriate?
  • Are concessions or approvals documented?
  • Are records of nonconformities retained?

Objective evidence to consider

  • NCR records
  • Deviation records
  • Inspection reports
  • Rework records
  • Disposition approvals
  • Customer concessions
  • Corrective action records

Clause 9 - Performance Evaluation

 

9.1 Monitoring, Measurement, Analysis and Evaluation

 

Audit questions

  • What QMS processes are monitored and measured?
  • Are appropriate performance indicators established?
  • Is customer satisfaction monitored?
  • Are quality trends analyzed?
  • Are results communicated to relevant personnel?
  • Are actions taken when performance does not meet expectations?

Objective evidence to consider

  • KPI dashboards
  • Quality metrics
  • Customer satisfaction data
  • Complaint trends
  • NCR trends
  • CAPA trends
  • Process performance reports

9.2 Internal Audit

 

Audit questions

  • Is an internal audit program planned?
  • Are audit frequency and scope determined based on process importance, changes and previous audit results?
  • Are auditors selected to maintain objectivity and impartiality?
  • Are audit criteria and scope defined?
  • Are audit findings communicated to relevant management?
  • Are corrective actions followed up?
  • Are audit records retained?

Objective evidence to consider

  • Annual audit program
  • Audit schedules
  • Audit plans
  • Auditor competency records
  • Audit checklists
  • Audit reports
  • Findings
  • Corrective action records
  • Audit closure records

Questions for the auditor

For each audit, consider asking:

  • (1) What process or requirement is being audited?
  • (2) What criteria are being used?
  • (3) What objective evidence was reviewed?
  • (4) What was found?
  • (5) Is the finding conforming, nonconforming or an observation/improvement opportunity?
  • (6) What action is required?
  • (7) Who owns the action?
  • (8) What is the target date?
  • (9) How will effectiveness be verified?

9.3 Management Review

 

Audit questions

  • Is management review conducted at planned intervals?
  • Are required QMS performance inputs reviewed?
  • Are audit results considered?
  • Are customer feedback and complaints considered?
  • Are process and product performance results reviewed?
  • Are nonconformities and corrective actions reviewed?
  • Are changes affecting the QMS considered?
  • Are opportunities for improvement identified?
  • Are management review decisions and actions recorded?

Objective evidence to consider

  • Management review agenda
  • Management review minutes
  • KPI reports
  • Audit results
  • Customer feedback
  • CAPA/NCR reports
  • Risk reports
  • Improvement actions
  • Action tracking records

Clause 10 - Improvement

 

10.1 General Improvement

 

Audit questions

  • Does the organization identify opportunities for improvement?
  • Are improvement opportunities evaluated and prioritized?
  • Are improvement actions integrated into QMS processes?
  • Is the effectiveness of improvement activities evaluated?

Objective evidence to consider

  • Improvement projects
  • Process improvement records
  • KPI trends
  • Employee suggestions
  • Management review actions
  • Quality improvement initiatives

10.2 Nonconformity and Corrective Action

 

Audit questions

  • Are nonconformities identified and controlled?
  • Is immediate correction or containment performed where necessary?
  • Are the causes of nonconformities investigated?
  • Is root cause analysis appropriate to the problem?
  • Are similar or recurring problems considered?
  • Are corrective actions implemented?
  • Are corrective actions reviewed for effectiveness?
  • Are QMS risks and opportunities updated when necessary?
  • Are records of nonconformities and corrective actions maintained?

Objective evidence to consider

  • NCRs
  • CAPAs
  • 5 Whys
  • Root cause analysis
  • Containment actions
  • Corrective action plans
  • Action owners
  • Target dates
  • Effectiveness reviews
  • Closure approvals

A useful CAPA audit trail

A strong corrective-action record should allow an auditor to follow the complete chain:

Problem → Containment → Investigation → Root Cause → Corrective Action → Implementation → Effectiveness Check → Closure

10.3 Continual Improvement

 

Audit questions

  • Does the organization continually improve the suitability, adequacy and effectiveness of its QMS?
  • Are quality trends used to identify improvement opportunities?
  • Are recurring problems analyzed?
  • Are audit results used to improve processes?
  • Are customer feedback and complaints used to identify improvements?
  • Does management evaluate whether improvement initiatives are achieving their intended results?

Objective evidence to consider

  • Improvement plans
  • KPI trends
  • Recurring NCR analysis
  • CAPA effectiveness
  • Customer feedback
  • Audit trends
  • Management review decisions

ISO 9001 Audit Findings

 

An audit should not stop when a checklist question has been answered.

When an auditor identifies an issue, the finding should be documented with enough information for the organization to understand and address it.

Depending on the organization's audit methodology, findings may be classified as:

  • Conforming
  • Nonconforming / Nonconformity
  • Observation
  • Opportunity for Improvement
  • Not Applicable, where justified

A useful finding record can include:

Field Purpose
Finding Number Unique identification
Audit Links finding to the audit
Clause / Requirement Identifies the relevant requirement
Process / Department Identifies where the finding occurred
Finding Type Nonconformity, observation, etc.
Description Clear statement of what was found
Objective Evidence Evidence supporting the finding
Responsible Person Owner of follow-up
Target Date Required completion date
Corrective Action Action required
Root Cause Cause of the problem
Effectiveness Verification that action worked
Closure QA/auditor closure

From Audit Finding to CAPA

 

For significant or recurring findings, the audit process may need to connect to the organization's nonconformance and CAPA processes.

A practical workflow is:

Audit → Finding → NCR → Investigation → Root Cause Analysis → Corrective Action → Effectiveness Analysis → Closure

This creates traceability between the original audit requirement and the corrective action taken.

It also helps Quality teams answer an important audit question:

"Show me what happened to this finding after it was identified."

ISO 9001 Audit Checklist : Auditor Preparation

 

Before beginning the audit, the audit team should consider:

Audit scope

  • What locations are included?
  • Which departments or processes are included?
  • Which products or services are covered?
  • Which requirements are being audited?

Audit criteria

  • ISO 9001 requirements
  • Internal procedures
  • Customer requirements
  • Regulatory requirements
  • Applicable organizational requirements

Audit team

  • Lead auditor
  • Supporting auditors
  • Process owners
  • Subject-matter experts where necessary

Audit evidence

Prepare to review:

  • Documents
  • Records
  • Employee interviews
  • Process observations
  • System records
  • KPIs
  • Quality events
  • Previous audit findings
  • Corrective actions

What Evidence Should an : ISO 9001 Auditor Look For?

 

A common mistake during internal audits is checking only whether a procedure exists.

An effective audit should examine both documented information and actual implementation.

For example:

Procedure says: Auditor should check:
Documents must be approved before release. Are current documents actually approved before employees use them?
Employees must be trained on revised documents. Can the organization demonstrate training or awareness for affected personnel?
CAPA effectiveness must be evaluated. Is there objective evidence that the corrective action actually addressed the cause?

The objective is to determine whether the QMS is implemented and effective, not merely documented.

How LuitBiz QMS Can Help : Manage ISO 9001 Audits

 

A checklist is useful for preparing and conducting an audit. The larger challenge is managing everything that happens before, during and after the audit.

LuitBiz QMS brings these quality processes together in one system.

Process How LuitBiz QMS Helps
Audit Management Create audits, define audit scope and criteria, assign checklist items or clauses to auditors, record evidence and findings, assign actions and track closure.
Document Control Control SOPs, policies, forms and other quality documents with controlled versions, approvals, access and audit history.
Nonconformance Management Record nonconformities from audits, production, suppliers, customers or other quality processes and track them through investigation and disposition.
CAPA Manage corrective and preventive actions with responsible persons, target dates, root cause analysis, action tracking and effectiveness review.
Supplier Quality Track supplier evaluations, supplier issues, nonconformances and corrective actions.
Complaint Management Capture customer complaints and connect them to investigations, root causes and corrective actions where required.
Change Control Manage quality-related changes through controlled requests, review, approval, implementation and records.
Quality Dashboards Give Quality and management visibility into audits, findings, NCRs, CAPAs, overdue actions and quality trends.

The result is a connected quality workflow rather than a collection of separate spreadsheets, documents and email threads.

ISO 9001 Audit Checklist - Download

 

Use this page as a starting point for your internal audit planning and customize the checklist to your organization's QMS, processes, risks, products and applicable requirements.

Download the free ISO 9001 Audit Checklist and use it to prepare your next internal audit by submitting the following form.


 

Important: This checklist is provided for general informational and audit-preparation purposes. It is not a substitute for the ISO 9001 standard, professional auditing guidance or advice from your certification body. Organizations should use the current applicable edition of ISO 9001 and determine how its requirements apply to their QMS.

 

Looking for a Modern Quality Management System?

See how LuitBiz QMS helps organizations automate quality processes to ensure ISO 9001 Compliance

Start Your Digital Transformation Journey

Frequently Asked Questions

What is an ISO 9001 audit checklist?

An ISO 9001 audit checklist is a structured set of audit questions and evidence prompts used to assess whether an organization's Quality Management System conforms to applicable ISO 9001 requirements and is effectively implemented.

What clauses should an ISO 9001 audit checklist cover?

A comprehensive checklist should address the applicable requirements in clauses 4 through 10, covering the organization's context, leadership, planning, support, operation, performance evaluation and improvement.

Is this an ISO 9001:2026 audit checklist?

This checklist is structured around the clause framework of ISO 9001 and is designed to support audits against the current edition. ISO 9001:2026 was published in September 2026 and replaced ISO 9001:2015 as the current edition. Organizations transitioning from the previous edition should confirm applicable transition requirements with their certification body.

What is objective evidence in an ISO 9001 audit?

Objective evidence is information that can be verified and used to demonstrate whether a requirement is being fulfilled. Examples include records, documents, system data, observations, measurements, interviews and other verifiable information.

What should happen after an ISO 9001 audit finding?

The organization should evaluate the finding, determine the appropriate correction or containment, investigate the cause where required, implement corrective action and verify effectiveness before closure.

Should every audit finding create a CAPA?

Not necessarily. The organization's QMS should define how findings and nonconformities are handled. The significance, recurrence, risk and nature of a finding can determine whether a formal corrective action or CAPA process is required.

How often should an internal ISO 9001 audit be conducted?

ISO 9001 does not prescribe one universal audit frequency for every process or organization. The internal audit program should consider factors such as process importance, changes affecting the organization, previous audit results and other relevant risks.

Can a checklist replace an ISO 9001 auditor?

No. A checklist is an audit aid. An effective audit also requires competent auditors who can evaluate objective evidence, understand the organization's processes and determine whether requirements are effectively implemented.

Can LuitBiz QMS manage ISO 9001 audits?

Yes. LuitBiz QMS is designed to support quality processes including document control, audit management, nonconformance management, CAPA, supplier quality, complaints, change management and quality dashboards.